Static analysis reads a file’s code and structure without running it, which catches obviously malicious code but misses anything that only reveals itself at runtime. Dynamic analysis runs the file inside an isolated environment and records what it actually does:… Read More "Integrated Malware Sandboxing for Faster EDR Investigations"
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95),… Read More "Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers"
Big Tech’s AI safety rift signals disruption and disparity for enterprises
Enterprise concerns While the debate is often framed as a choice between slowing innovation and strengthening oversight, analysts said enterprises should focus less on which approach prevails and more on the operational consequences already taking shape. “Divergent safety approaches will… Read More "Big Tech’s AI safety rift signals disruption and disparity for enterprises"
Cyber Op Targets South Korean Media & Automotive Sectors
Stealthy attacks on South Korean automotive and media firms have given an espionage group access to victims’ networks — operating, in some cases, since early 2025. In an analysis this week, Rapid7 attributed the attack to North Korean advanced persistent… Read More "Cyber Op Targets South Korean Media & Automotive Sectors"
Best Dark Web Monitoring Services for Business
What dark web monitoring does for a business Most security stacks still find out about stolen credentials the hard way: when an attacker logs in with them. Sometimes the first warning sign is a customer complaint or a call from… Read More "Best Dark Web Monitoring Services for Business"
First Agentic AI Data Breach Reported to Spanish Regulator
The Spanish Data Protection Agency (AEPD) has published details of the first notification of a personal data protection breach executed by design through an AI agent. Investigation into the attack is continuing, and the AEPD uses its words carefully. Nevertheless,… Read More "First Agentic AI Data Breach Reported to Spanish Regulator"
What to Do First in an Incident Response Investigation
Key Takeaways The key focus of an incident response investigation is to create sufficient context to know what to do first before disrupting an incident. Early evidence preservation is critical for determining what the attacker did and preventing the loss… Read More "What to Do First in an Incident Response Investigation"
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
Ravie LakshmananSep 16, 2026Vulnerability / Web Security A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0… Read More "Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution"
Oracle’s September patches put Fusion Middleware back in the hot seat
It also included a warning for organizations running older Oracle releases. The fixes are provided only for supported versions, the company said, adding that “Product releases that are not under Premier Support or Extended Support are not tested for the… Read More "Oracle’s September patches put Fusion Middleware back in the hot seat"
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce P
Attackers have been uploading PHP webshells to WordPress sites through a critical flaw in a third-party WooCommerce plugin, four months after a fix was released. In a technical write-up published on September 14, Wordfence said its firewall had blocked more than… Read More "PHP Webshell Campaign Targets WordPress Through Critical WooCommerce P"